CVE-2020-25657: High severity m2crypto vulnerability
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
Other sources
All released versions of m2crypto are vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
Upstream issue:
https://gitlab.com/m2crypto/m2crypto/-/issues/285
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25657?
CVE-2020-25657 is a vulnerability in all released versions of m2crypto that makes them vulnerable to Bleichenbacher timing attacks in the RSA decryption API.
How does CVE-2020-25657 affect the affected software?
CVE-2020-25657 can lead to the compromise of confidentiality in the affected software.
What is the severity of CVE-2020-25657?
The severity of CVE-2020-25657 is high, with a CVSS base score of 7.5.
How can I fix the CVE-2020-25657 vulnerability in m2crypto?
Update to the latest version of m2crypto or apply the patches provided by the vendor.
Where can I find more information about CVE-2020-25657?
You can find more information about CVE-2020-25657 on the CVE website (https://www.cve.org/CVERecord?id=CVE-2020-25657) and the NIST National Vulnerability Database (https://nvd.nist.gov/vuln/detail/CVE-2020-25657).